📦 Nginx

by F5

🔍 What is Nginx?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2017-20005

CRITICAL CVSS 9.8 Jun 6, 2021

This vulnerability is a buffer overflow in NGINX's autoindex module when processing file modification dates with years exceeding four digits. It affects NGINX servers with autoindex enabled, allowing ...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2021-3618

HIGH CVSS 7.4 Mar 23, 2022

ALPACA is a TLS protocol confusion attack that allows man-in-the-middle attackers to redirect traffic between different services sharing compatible certificates (like wildcard or multi-domain certific...

CVE-2025-23419

MEDIUM CVSS 4.3 Feb 5, 2025

This CVE describes a client certificate authentication bypass vulnerability in nginx when multiple server blocks share the same IP/port. Attackers can exploit TLS session resumption to bypass client c...